[SYSS-2026-071]: GDCM (Grassroots DICOM) - Format String (CWE-134)
SySS disclosed an unpatched medium-risk format-string flaw in GDCM 3.3.0, with no CVE assigned.
SySS published advisory SYSS-2026-071 describing a format-string vulnerability (CWE-134) in GDCM (Grassroots DICOM) 3.3.0, the tested version. Risk is rated medium and the solution status is open, so no fix is listed. The vendor was notified on 2026-07-24 and the issue was disclosed on 2026-09-23. No CVE has been assigned and exploitation is not reported.